OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103256

HIGH · CVSS 7.1 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Versions of n8n prior to 2.39.6 and between 2.40.0 and 2.40.1 are vulnerable to a credentials leak that exposes unencrypted usernames and passwords to unvalidated hosts. This flaw allows attackers with permission to update credentials to redirect sensitive information to arbitrary destinations, effectively bypassing security measures. Organizations using affected versions should prioritize updating to mitigate the risk of credential theft and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103256
Severity
HIGH
CVSS
7.1
EPSS
0.21%

Original NVD Description

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.